PT-2025-5971 · Apache · Apache Kvrocks

Sergey Volosatov

·

Published

2025-02-07

·

Updated

2025-07-16

·

CVE-2025-25069

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Kvrocks versions 1.0 through 2.11.0
Description A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks did not detect if Host: or POST appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can be dangerous when chained with SSRF. This issue is similar to a previously identified vulnerability in Redis.
Recommendations For Apache Kvrocks versions 1.0 through 2.11.0, upgrade to version 2.11.1, which fixes the issue. As a temporary workaround, consider restricting access to the database operations that can be triggered by the vulnerability until the update is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-25069

Affected Products

Apache Kvrocks